1. https://appdevelopermagazine.com/security
  2. https://appdevelopermagazine.com/salesforce-data-breach-linked-to-tenable-via-salesloft-drift/
9/12/2025 7:05:19 AM
Salesforce data breach linked to Tenable via Salesloft Drift
Cybersecurity,Threats, Artificial intelligence,Malicious cyber campaigns,Salesforce Security,Data Breach,SaaS,Security, Development
/salesforce-data-breach-linked-to-tenable-via-salesloft-drift-app-developer-magazine_o777xcew.jpg
App Developer Magazine
Salesforce data breach linked to Tenable via Salesloft Drift

Security

Salesforce data breach linked to Tenable via Salesloft Drift


Friday, September 12, 2025

Richard Harris Richard Harris

A recent investigation into the Salesforce data breach linked to Tenable highlights risks in third-party SaaS integrations and underscores the need for organizations to strengthen access controls and monitor connected apps.

A recent Salesforce data breach involving the Salesloft Drift integration has affected multiple organizations, including cybersecurity company Tenable. The company confirmed that limited customer contact and support case data were exposed but emphasized that no core product data was compromised.

Scope of exposed information

Tenable reported that information accessed included names, email addresses, phone numbers, business regions, and details submitted through support case subject lines and descriptions. The company said core platform and product data were not impacted, according to its investigation and official disclosures. These details reflect Tenable’s own statements about the incident. 

How attackers exploited Salesforce integrations

Investigators have tied the breach to an ongoing cyber campaign targeting organizations that use Salesforce with the Salesloft Drift marketing tool. Reports from outlets like CRN and Cybersecurity News note that attackers leveraged compromised OAuth tokens and credentials to extract sensitive data. Other affected companies reportedly include Palo Alto Networks, Zscaler, Cloudflare, Proofpoint, and CyberArk. 

Tenable’s remediation efforts

Following its discovery of the breach, Tenable says it:

  • Revoked and rotated credentials for Salesforce and related services
  • Disabled and removed the Drift integration from its Salesforce environment
  • Hardened access controls across its SaaS infrastructure
  • Applied threat intelligence from Salesforce and third-party security researchers
  • Deployed continuous monitoring tools to detect further suspicious activity

Tenable stressed that its quick response was meant to reduce the risk of additional exposure.

Representation of cybersecurity

Salesforce data breach highlights SaaS supply chain risks

The Salesforce–Salesloft Drift breach reflects a growing trend of attackers targeting SaaS ecosystems rather than traditional endpoints. As organizations integrate more third-party apps into platforms like Salesforce, the risk of exposure rises. Experts recommend stronger identity and access management, frequent credential rotation, and strict least-privilege policies.

Industry reactions

CRN reported that security vendors have begun auditing Salesforce integrations in response to the campaign. Salesforce has not released detailed findings about the attack, though third-party researchers have confirmed that stolen tokens and integration misconfigurations were likely factors.

Nick Percoco, chief security officer at cryptocurrency exchange Kraken, told Reuters in related reporting that similar phishing and impersonation schemes remain common. He noted that the challenge of validating legitimate recruiters, partners, or SaaS connectors is growing as attackers refine their methods.

Best practices for organizations

Cybersecurity specialists recommend the following to help mitigate risks:

  1. Audit all third-party integrations to confirm necessity and tighten permissions.
  2. Implement strong identity and access management policies with multi-factor authentication.
  3. Monitor and rotate API keys and OAuth tokens to reduce exposure time.
  4. Use SaaS Security Posture Management (SSPM) solutions for visibility into misconfigurations.
  5. Run tabletop exercises simulating SaaS-based supply chain breaches to improve readiness.

Transparency and disclosure

Tenable’s approach reflects growing industry pressure for transparency. While no core data or platform systems were compromised, the breach illustrates how third-party connections can create unintended entry points for attackers.

As supply chain attacks become more common, customers and vendors are placing a higher priority on full disclosure of security incidents to maintain trust. Analysts see this as part of a broader shift toward proactive security communication.

The Salesforce data breach tied to Tenable and other vendors underscores the complexity of securing interconnected SaaS environments. While Tenable’s investigation and actions appear to have limited further risk, experts emphasize the importance of reviewing integrations, implementing zero-trust principles, and strengthening response plans.

Organizations relying on cloud-based tools should view this event as a reminder to adopt continuous monitoring, limit access permissions, and proactively address vulnerabilities before they are exploited.






Subscribe to App Developer Magazine

Become a subscriber of App Developer Magazine for just $5.99 a month and take advantage of all these perks.

MEMBERS GET ACCESS TO

  • - Exclusive content from leaders in the industry
  • - Q&A articles from industry leaders
  • - Tips and tricks from the most successful developers weekly
  • - Monthly issues, including all 90+ back-issues since 2012
  • - Event discounts and early-bird signups
  • - Gain insight from top achievers in the app store
  • - Learn what tools to use, what SDK's to use, and more

    Subscribe here



Featured Stories


Tether QVAC SDK Powers AI Across Devices and Platforms
Tether QVAC SDK Powers AI Across Devices and Platforms Wednesday, April 22, 2026


APAC 5G expansion to fuel 347B mobile market by 2030
APAC 5G expansion to fuel 347B mobile market by 2030 Tuesday, April 21, 2026




How AI is causing app litter everywhere
How AI is causing app litter everywhere Tuesday, April 21, 2026


The App Economy Is Thriving
The App Economy Is Thriving Monday, April 20, 2026


NIKKE 3.5 anniversary update livestream coming soon
NIKKE 3.5 anniversary update livestream coming soon Friday, April 17, 2026


New AI tool targets early dementia detection
New AI tool targets early dementia detection Thursday, April 16, 2026


Jentic launch gives AI agents api access
Jentic launch gives AI agents api access Wednesday, April 15, 2026


Experts warn ai-generated health content risks misinterpretation without human oversight
Experts warn ai-generated health content risks misinterpretation without human oversight Wednesday, April 15, 2026


Ludo.ai Unveils API and MCP Beta to Power AI Game Asset Pipelines
Ludo.ai Unveils API and MCP Beta to Power AI Game Asset Pipelines Tuesday, April 14, 2026


AccuWeather Launches ChatGPT Integration for Live Weather Updates
AccuWeather Launches ChatGPT Integration for Live Weather Updates Tuesday, April 14, 2026


Stay Updated

Sign up for our newsletter for the headlines delivered to you

SuccessFull SignUp

Get More App News



/sites/themes/prod/assets/js/less.js"> ' ' %>